Jump to content

free780

Members
  • Posts

    3,614
  • Joined

  • Last visited

Everything posted by free780

  1. You may be able to use conditional access to stop authentication to Exchange Online out of hours. I think the token lasts 8 hours though. Maybe a transport rule could do it. But the larger question is, if your staff are remote working is why.
  2. JISC/Janet had similar a few years ago. They increased security and mitigations. They have increased costs due to the government pulling some funding. Is it a case of you get what you pay for? I used to work at a school and we never had any issues with Exa apart from someone cutting through some fibre and Exa called us downtime was only 2-3 hours.
  3. I just had to parse that outcome. Activations stopped working on new and existing devices. In the past I could delete the AAD User and activation would work. So yes you'll need to move to DBL. As a temporary measure I moved to SCA. The limit for this isn't known to n terms of users moving from device to device. The challenge will be getting a 100% hybrid joined Fleet and Office up to date.
  4. Yep the Java edition won't really work as you can't federate/sync users. The subscription model seems to be where everything is going. I wouldn't be surprised if more software requires signing in like Minecraft edu and Adobe CC. Once you have AzureAD setup it's fairly easy.
  5. I wish the Azure connector existed a year ago. https://helpx.adobe.com/uk/enterprise/using/sso-setup-azure.html Looks much easier than the sync tool and no on prem server required.
  6. From MS' point of view LTSC is only meant for boiler control PCs etc. If your developing for current versions of Windows you'd be using SAC.
  7. I wasn't aware of the group limit. I've done the same setup but our SSO just requires the user to enter our domain name. Just make sure you setup some notifications about certificates expiring. Ideally you want the Shared Device Licensing rather than named.
  8. Visual Studio 2017 isn't supported on LTSC. Maybe MS are making good on that requirement. Can you try a SAC version?
  9. Sorry I may have got that wrong. Probably best to ask your reseller.
  10. If the users get used to it yes they can just deactivate a PC when the prompt comes up. Even with SDL they have to type the domain name and press tab to SSO (its not pass thru). So either way users are going to get something. With named licensing they are able to put the software on personal devices unless you tie in authentication with AzureAD etc and block sign ins to Adobe from outside your network.
  11. Well DBA stopped working over the summer. DBL is the new way of doing it. You need to be licenced with A3 and have hybrid join setup. https://docs.microsoft.com/en-us/deployoffice/device-based-licensing
  12. If your users have 1:1 devices go for named licensing. You only get 2 activations per user licence. If you have shared lab environments you need the shared device licensing.
  13. For those using both. How do you do it? Administrating Office 365 takes a lot of time. I guess looking after Gsuite and Office 365 is your user count is 500 may be easier than 11000 users.
  14. I've worked for 2 FE Colleges both went with Office 365. I've looked at Gsuite but I don't think it prepares students for the work place compared to Office 365. The real killer feature from a admin perspective is that using a hybrid model always takes into consideration your existing Windows environment. Granted I wish MS would do a 365 Chromebook.
  15. I miss Bloxx. The support was brilliant. I guess with Smoothwall there's a lot of orgs using it.
  16. The apps get provisioned upon login. The record of this is in the registry and buried in Program Files its not in the user profile. I believe they only function correctly in local profiles or with a FS Logic container.
  17. OK I now have Device Based Licencing functioning on Hybrid Devices. Make sure you update your ADMXs and enable the new policy.
  18. Well I guess the proper way to do it is subscription licensing linked to the user for Windows 10.
  19. I think I added a command to sync time with our Smoothwall box and use NTP. Because winpe isn't domain joined you can't sync against a DC. Also check the timezone in winpe. The no task sequences is usually because SCCM creates a device called Unknow if it doesn't recognise the device. Ideally you have you devices all in SCCM, even new devices but you need the Mac Address and SMSBIOSGUID I think. If you reuse devices and set a new name you might have a device within SCCM. You can search via mac address now to find it.
  20. There are some issue with hybrid devices not working at present. The old DBA was US only.
  21. BTL SecureAssess exam clients will need updating. But I haven't seen much evidence of this yet.
  22. I don't know. There is a GPO setting for IE and Edge that disables flash. MS could just set that as enforced. They usually make allowances for those in enterprise who need to run legacy plugins. They might do a whitelist for IE only flash player.
  23. I just point people to use IE for sites that require flash player. I state that Flash will EOL in 2020.
  24. Put the /qn at the end of the command.
  25. Strip it out of the run key (per user) It runs onedrivesetup.exe on first login.
×
×
  • Create New...